PT-2013-5500 · Ibm+2 · Ibm Java Sdk+3

Published

2013-11-07

·

Updated

2017-08-29

·

CVE-2013-5375

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Java SDK versions 5.0.0 before SR16 FP4 IBM Java SDK versions 6.0.0 before SR15 IBM Java SDK versions 6.0.1 before SR7 IBM Java SDK versions 7.0.0 before SR6
Description The issue allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL. This could occur when untrusted code is executed under a security manager, or when the IBM SDK, Java Technology Edition has been associated with a web browser for running applets and Web Start applications, allowing code running under a security manager to access restricted classes.
Recommendations For IBM Java SDK version 5.0.0, update to SR16 FP4 or later. For IBM Java SDK version 6.0.0, update to SR15 or later. For IBM Java SDK version 6.0.1, update to SR7 or later. For IBM Java SDK version 7.0.0, update to SR6 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-5375
RHSA-2013:1507
RHSA-2013:1508
RHSA-2013:1509
RHSA-2013:1793
RHSA-2013_1507
RHSA-2013_1508
RHSA-2013_1509

Affected Products

Ibm Aix
Ibm Java Sdk
Red Hat
Suse